CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-7044
AJ Square Free Polling Script - SQL Injection via ques Parameter
CVE-2008-7040
Yellow Swordfish Simple Forum - SQL Injection via u Parameter
CVE-2008-7038
My_eGallery - SQL Injection via gid Parameter
CVE-2008-7033
Simple Shop Galore (com_simpleshop) - SQL Injection via Section Parameter
CVE-2008-7030
Site2Nite Real Estate Web - SQL Injection via Username or Password Field
CVE-2008-7003
The Rat CMS Alpha 2 - SQL Injection via login.php user_id and password Parameters
CVE-2008-6992
GreenSQL Firewall - SQL Injection Protection Bypass via WHERE Clause Expression
CVE-2008-6991
cmsbright - SQL Injection via id_rub_page Parameter
CVE-2008-6990
ezphotogallery 2.1 - SQL Injection via Gallery Password Parameter
CVE-2008-6989
ezphotogallery 2.1 - SQL Injection via gallery.php Username Parameter
CVE-2008-6986
Zen Cart 1.3.0-1.3.8a - SQL Injection via products_id Array Parameter
CVE-2008-6985
Zen Cart 1.2.0-1.3.8a - SQL Injection via Shopping Cart ID Parameter
CVE-2008-6980
phpAdultSite CMS - SQL Injection via results_per_page Parameter
CVE-2008-6970
UBB.threads < 7.3.1 - SQL Injection via Forum[] Array Parameter
CVE-2008-6968
Pligg CMS 9.9.5 - SQL Injection via Category or ID Parameter
CVE-2008-6964
X7 Chat 2.0.5 - SQL Injection via Login Password Field
CVE-2008-6952
MauryCMS <= 0.53.2 - SQL Injection via Rss.php c Parameter
CVE-2008-6950
Bankoi WebHosting Control Panel 1.20 - SQL Injection via Login Username or Password Field
CVE-2008-6941
TurnkeyForms Web Hosting Directory - SQL Injection via Login Password Field
CVE-2008-6923
Joomla com_content 1.0.0 - SQL Injection via Itemid Parameter
CVE-2008-6917
ExoPHPDesk 1.2 Final - SQL Injection via Username Parameter
CVE-2008-6911
BrewBlogger 2.1.0.1 - SQL Injection via loginUsername Parameter
CVE-2008-6907
2532gigs 1.2.2 - SQL Injection via Username and Password Parameters
CVE-2008-6892
Peel 3.1 - SQL Injection via rubid Parameter
CVE-2008-6890
ASP Forum Script - SQL Injection via messages.asp message_id Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High